logo

LastPass Customer Data Stolen in Klue Supply Chain Breach

ID: 3f9c2c66-e9a9-5d66-82e1-d1b8f63d6621

STIX ID: report--3f9c2c66-e9a9-5d66-82e1-d1b8f63d6621

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-23

Date Updated: 2026-06-24

Author: Do Son

...
...

LastPass confirmed that attackers who breached Klue stole OAuth tokens and used them to access LastPass’s Salesforce instance, exposing CRM contact details and support case data (names, emails, phone numbers, addresses). LastPass says customer vaults remain secure, has revoked Klue access and rotated tokens, and opened investigations with Klue, Salesforce, and law enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.